7500 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-0406
Software Genérico General
6.1
MEDIUM
EPSS
21.5%
2024 CWE-22 1 PoC

A flaw was discovered in the mholt/archiver package. This flaw allows an attacker to create a specially crafted tar file, which, when unpacked, may allow access to restricted files or directories. This issue can allow the creation or overwriting of files with the user's or application's privileges using the library.

CVE-2024-11846
TravelTour Web
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2024-44872
Software Genérico Web
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

A reflected cross-site scripting (XSS) vulnerability in moziloCMS v3.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload.

CVE-2024-8056
MM-Breaking News Web Windows
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The MM-Breaking News WordPress plugin through 0.7.9 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers

CVE-2024-13218
Fast Tube Web Windows
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The Fast Tube WordPress plugin through 2.3.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-41504
Software Genérico Web
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

Jetimob Plataforma Imobiliaria 20240627-0 is vulnerable to Cross Site Scripting (XSS). In the "Oportunidades" (opportunities) section of the application when creating or editing an "Atividade" (activity), the form field "Descrico" allows injection of JavaScript.

CVE-2024-13853
SEO Tools Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
1.9%
2024 1 PoC

The SEO Tools WordPress plugin through 4.0.7 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2024-22359
UrbanCode Deploy Web
6.1
MEDIUM
EPSS
0.2%
2024 CWE-79 1 PoC

IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.20, 7.1 through 7.1.2.16, 7.2 through 7.2.3.9, 7.3 through 7.3.2.4 and IBM DevOps Deploy 8.0 through 8.0.0.1 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 280897.

CVE-2024-26317
Software Genérico General
6.1
MEDIUM
EPSS
0.1%
2024 1 PoC

In illumos illumos-gate 2024-02-15, an error occurs in the elliptic curve point addition algorithm that uses mixed Jacobian-affine coordinates, causing the algorithm to yield a result of POINT_AT_INFINITY when it should not. A man-in-the-middle attacker could use this to interfere with a connection, resulting in an attacked party computing an incorrect shared secret.

CVE-2024-10908
lm-sys/fastchat General ⚡ nuclei
6.1
MEDIUM
EPSS
1.0%
2024 CWE-601 0 PoCs

An open redirect vulnerability in lm-sys/fastchat Release v0.2.36 allows a remote unauthenticated attacker to redirect users to arbitrary websites via a specially crafted URL. This can be exploited for phishing attacks, malware distribution, and credential theft.

CVE-2024-13112
WP MediaTagger Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
1.5%
2024 1 PoC

The WP MediaTagger WordPress plugin through 4.1.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-21020
Complex Maintenance, Repair, and Overhaul Web Database
6.1
MEDIUM
EPSS
0.3%
2024 1 PoC

Vulnerability in the Oracle Complex Maintenance, Repair, and Overhaul product of Oracle E-Business Suite (component: LOV). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Complex Maintenance, Repair, and Overhaul. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Complex Maintenance, Repair, and Overhaul, attacks may significantly impact additional products (scope change). Successful attacks of th

CVE-2024-33305
Software Genérico Web
6.1
MEDIUM
EPSS
0.1%
2024 1 PoC

SourceCodester Laboratory Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via "Middle Name" parameter in Create User.

CVE-2024-6223
Send email only on Reply to My Comment Web Windows
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The Send email only on Reply to My Comment WordPress plugin through 1.0.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2024-8054
MM-Breaking News Web Windows
6.1
MEDIUM
EPSS
0.3%
2024 1 PoC

The MM-Breaking News WordPress plugin through 0.7.9 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.

CVE-2024-10858
Jetpack Web Windows
6.1
MEDIUM
EPSS
0.0%
2024 2 PoCs

The Jetpack WordPress plugin before 14.1 does not properly checks the postmessage origin in its 13.x versions, allowing it to be bypassed and leading to DOM-XSS. The issue only affects websites hosted on WordPress.com.

CVE-2024-21063
PeopleSoft Enterprise HCM Benefits Administration Database
6.1
MEDIUM
EPSS
0.1%
2024 1 PoC

Vulnerability in the PeopleSoft Enterprise HCM Benefits Administration product of Oracle PeopleSoft (component: Benefits Administration). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where PeopleSoft Enterprise HCM Benefits Administration executes to compromise PeopleSoft Enterprise HCM Benefits Administration. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or compl

CVE-2024-3478
Herd Effects Web Windows
6.1
MEDIUM
EPSS
0.1%
2024 1 PoC

The Herd Effects WordPress plugin before 5.2.7 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, such as deleting effects via CSRF attacks

CVE-2024-4149
Floating Chat Widget: Contact Chat Icons, WhatsApp, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button Web Windows
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The Floating Chat Widget: Contact Chat Icons, WhatsApp, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button WordPress plugin before 3.2.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-3590
LetterPress Web Windows
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The LetterPress WordPress plugin through 1.2.2 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks, such as delete arbitrary subscribers